Authorization Service/Agent/App #603
Replies: 2 comments
-
The meetings is scheduled for 2023-12-12 #555 |
Beta Was this translation helpful? Give feedback.
-
Notes from 2023-12-12 Present
Launcher App
Silvan, Benoit and Daniel plan to work on it. Solid Wallet was re-naming for proposa/funding purposes, essentially nothing different but the very idea of the LauncherApp. Arne woked on What runs on user device(s) and what on the server somewhere in the cloud? There is also a server side, not only the client in the browser. It is considered the first app you get, just as your WebID and pod. It launches all the other apps and manages them. It manages the apps and stores the credentials. European Identiy Framework, blockchain based. Can be client-server or server-server communication. One potential use of HttpSig in the context of Notifications Protocol:
Launcher App Explorationhttps://launcher-exploration.inrupt.app/ It uses SAIearly playlist with demos https://www.youtube.com/watch?v=IXzdH1JqcOA&list=PLXBho_YohPB09B_ecOsABoI8Dc67v1H4O |
Beta Was this translation helpful? Give feedback.
-
Over the last few years, we can see a common direction independently emerging in different solid-based efforts.
A dedicated party focus and responsible for setting access policies.
One of the examples, which I'm the most familiar with by co-editing the spec and maintaining the typescript implementation, is SAI Authorization Agent.
Another example is Inrupt's Access Grant Service
Yet another example is LauncherApp
I also believe that SolidOS provides some additional authorization features, for example, special treatment when setting access to all the contacts in a contact group.
Since Authorization often depends on the user's social graph, the party responsible for authorization has often full access to that social graph. For example in SAI, a regular app can't set any access policies but it can redirect the user to their authorization agent indicating the resource they would like to share.
SAI's Agent Registry is fully managed by the Authorization Agent. Most interactions between two social agents depend on them having established reciprocal Social Agent Registrations.
Beta Was this translation helpful? Give feedback.
All reactions